> Since the hack, officials restored their website and posted a message announcing they are rebuilding the agency's entire network from scratch. Even if the hacker claims they deleted backups, the agency appears to have had an offline copy, otherwise things would have gotten really messy over the coming months in Romania.
So it seems not all has been lost. I was worried about the societal implications of being unable to prove land ownership but it seems that may be avoided.
I'm skeptical that they not missing at least a week's or so worth of land title registry transactions, if the only thing they have left is offline, because offline backups are not made after every single transaction.
If the hacker was targeting the erasure of a particular recent transaction, they may well have succeeded. And by deleting numerous others, they have plausible deniability in the subsequent dispute over the property. If you just wipe a record that is related to you, and the manipulation is discovered (which it will be, one way or another), you are part of a narrow circle of suspects.
When I worked at a stressful place I was worried not only of our version control getting damaged but also someone deciding they had had enough and doing damage on their way out.
I had a copy of our code on media in my desk labeled “promotion” and updated it every month. In retrospect someone going through my desk would have assumed blackmail material and been disappointed to find only code.
About 15% of the UK's land parcels are not in any land registry database, because recording there only became compulsory in 1990, so if an event like a sale/morgtage didn't happen to a property since then, it might not be registered. Regardless of the land registry, the ownership can still easily be proven.
A close relative, government employee, was in charge of building a new application. They have nobody in that entire organization of several thousands people that know how to write specifications for an IT application, nobody that knows how to design, test and deploy it. This is because some government employees have decent salaries, but in IT the private sector is paying a lot more, so almost anyone remotely competent is going to the private sector. So in this case an organization of non-IT people had to deal with the contract and all the associated problems - there is no need to guess, it did not go well. That kind of project could have been done properly with ~ 10% of the budget in the same timeline.
I have a friend that worked as a developer in such a government IT project. The project cost was ~ 5-10 times what was worth, a chain of sub-contractors did the work, less than ten competent people doing the project, charged by the bid winner for over 100 people and actual staff was around 70 at most, for a short period of time.
Both projects above are in Romania. Lack of competent people in the projects, especially in decision roles, was the main problem.
As a Romanian I can tell you that most of the corruption happens through "dedicated contracts", or outright syphoning.
In this case I expect an underpaid employee, and at most an incompetent nephew of someone. They had no reason to have an .authorized_keys file in the webroot of the website, and yet they did.
If you want to know what "dedicated contracts" look like in practice they are overly specific requirements than can only match a single business. The best example that comes to mind was when one county needed to buy busses (or vans) and the maximum length admitted was bellow the most common options, but as luck would have it a nephew of a cousing of someone with decision power (or something like that) just so happened to be the one importing cars that precisely matched the specs.
An update from the land registry (the truthfulness of this remains to be seen depending on how fast this comes back online):
ANCPI announced that it had begun migrating its applications to Romania’s Government Cloud. The operation is being coordinated by the Special Telecommunications Service (STS) and is expected to be completed on Wednesday, July 22.
After the migration, authorized institutions will inspect the applications and data and prepare a report on the condition of the systems and any additional measures required. Based on that report, ANCPI will announce an estimated date for restoring its applications. Services will be brought back online gradually, according to operational priorities.
ANCPI says it is rebuilding its database from backup copies stored in several locations. The agency rejected reports suggesting that it did not have sufficient backups, explaining that the use of multiple storage locations provides redundancy and allows data to be restored after cybersecurity incidents.
According to ANCPI, affected systems must remain isolated until every identified vulnerability has been addressed. Although shutting down the services has caused temporary inconvenience, the agency says the measure was necessary to protect the data and ensure that operations restart safely and reliably.
The restoration of the IT infrastructure is described as a complex process being conducted in cooperation with the relevant authorities. ANCPI has also confirmed that a criminal investigation is underway, but no official conclusions can yet be released.
The agency warned that claims circulating publicly about the alleged consequences of the attack are not based on official information and do not reflect the current state of the investigation.
My ex was late from work once a week because the company did commercial real estate logistics (sort of similar domain here) and she had the job of going to the secure data center and grabbing a backup disk out of the cage and transferring it to a safety deposit box.
The dumb thing was the bank was two blocks from the data center and less than eight (six?) from the office so catastrophic events might have hit both or all three. The owner kept a second copy at his house, and that was the only geographically separated copy.
One of the lessons (and subsequent data integrition / continuity of business practices) learned from the 9/11 attacks in New York City, and destruction of both primary and secondary data stores of multiple entities (as well as several emergency-response agencies at various government levels from city to federal) was that essential data and operational roles need to be redundant across very widely-separated locations.
E.g.: from "Discussion note prepared by staffs of the Federal Reserve, the New York State Banking Department, the Office of the Comptroller of the Currency, and the Securities and Exchange Commission, for discussion at a meeting on February 26, 2002 at the Federal Reserve Bank of New York":
[I]t was clear that business continuity planning had not fully taken into account the potential for wide-area disasters and for major loss or inaccessibility of critical staff. Contingency planning at many institutions generally focused on problems with a single building or system. Some firms arranged for their backup facilities to be in nearby buildings on the assumption that, for example, a fire might incapacitate or destroy a single facility. Very few planned for an emergency disrupting an entire business district, city, or region. As a result, some firms lost access to both their primary and backup facilities in the aftermath of the September 11 events, severely disrupting their operations.
Geographic distances were rarely considered prior to 9/11. Most companies were comfortable replicating data intercampus or to a facility within a few miles of a primary data center. A few firms, such as Nasdaq, actually replicated data out of state.
Terrorist attacks, natural disasters, widespread power and other failures, etc., can all have impacts across many kilometres, possibly many hundreds. Redundancy equates to survivability here.
More broadly, information and data services are fundamentally about risk management and disaster response, as realised during 9/11 (as well as multiple earlier and subsequent incidents) in ways which weren't fully realised at the turn of the millennium. Or even today in some organisations.
Make backups. Test backups. Practice switchovers between primary and secondary (or multiple redundant) operations. And keep those resources and facilities widely separated.
> HuggingFace got hacked by an AI. What stuck out to me was the guardrail asymmetry. The attacker had no constraints, but HF's response ran afoul of the abuse guardrails, forcing them into an unplanned switch to local models.
This, to me, is the more interesting bit of the article.
I don't really know what a good solution looks like, but yeah, that's annoying.
arte.tv released a documentary about measuring and registering land just a month ago @ https://www.youtube.com/watch?v=fl7AfiJs5Gk (Romania: The Unmeasured Land | ARTE.tv Documentary)
Amateurs. Everybody knows you should never wipe databases. You should install a cronjob that makes a random, unrecoverable change on a regular (but random) basis.
The UK used to have a distributed system - everyone had to have a solicitor store "deeds" of their property, which were a sort of paper blockchain of all the transactions the land had been in since - I don't know, since records began I guess. Since we got a centralised land registry cheaper solicitors have binned these, but some properties still have them as a historical record.
Not sure what you mean by 'binned'. In some Common Law jurisdictions the deed document represents the property and whoever psychically holds of the deed controls the property. Any centralized recording system merely records the last known status of the deed and additional information such as the nominal owner, mortgage holders, etc.
There also used to be bearer bonds. In part because of concerns about money laundering, a lot of more or less untraceable large monetary instruments have gone away.
Those started with money changers and long distance travel did they not?
Before phones, if you moved between two affluent areas there was enough surplus capital in both that instead of hauling a heavy chest of silver coins between them and risking getting Robin Hooded you turn your coins in at one end of the trip and get reimbursed by a fellow in the same money handling cooperative at the other end, and then they would square their books through traders moving money the opposite direction or if necessary by armed escort.
There are MMO economies that either ban the flow of real money into the game, or only allow it to enter the game and not leave. In the case of the latter, poorer players trade their time and skill for something transferable in the game, such as rare items, or in the case of Eve Online, one free month of play time. There are Eve players who only ever payed for the first couple months in the game and then found a revenue stream that was subsidized by other players buying excess play time and selling it in-game when the demand drives the price up high enough to be attractive.
There's a growing (retarded) perspective, not only here in Romania but in most of the EU, that we must digitalize at all costs; this itself is obviously not a problem, but it usually comes with the removal of the "traditional" options too. The same goes for payments (removal of cash) and basically every aspect of the administration/society where this could be applied. The most recent concrete example for Romania is the mandatory digital signature by ANAF (IRS equivalent) for all companies.
Unlike other regions of the West: NA/WE/rest of the West (SK, JP, etc.), in EE, people (*younger generations, explained below) don't often think about the aspects of confidentiality that much, or if they do, they usually apply it incorrectly (either IRL [filming in public] or online ["I've accepted a draconian TOS that gives the company rights to all of my data, but I haven't actually read any of it, and now I'm invoking my "GDPR rights" against said company."]).
It does not take a genius or a historian to observe that while the older generations do not have this "problem" (they're very skeptical of the gov. [at least in certain aspects], in an almost american fashion — explained by the fact that they've experienced communism), younger generations position themselves in the extreme opposite; they despise the older generations ("boomers") for being luddites and somehow blame them for the gap in civilizational progress between WE and EE. There is a legitimate point here, of course, but it should be noted that the argument is almost always presented in an emotional, overwhelmingly irrational fashion, and almost never includes comparisons between the centralization done by the state in the past [communists] and the new one attempted by current govs [but digitalized]. (This delves into a broader socio-cultural divide between the generations that includes other aspects like religion, traditions, etc.)
The biggest portion of the so-called "IT people" who call for this "digitalization wave" are midwits, "inverse luddites" (they don't care about the implications), and, in smaller numbers, grifters and second-order beneficiaries (on the "digitalization" gov. projects). Obviously, it should be mentioned that, despite progress, nepotism and corruption are still present, and there are cases where gov. contracts are not given to the best candidate.
As a person who's both working in the IT sector and not a boomer (despite the impression of my comment), "we" should be careful about enabling totalitarians in our endeavors."Hackers" is just one reason out of a multitude of other reasons for not abandoning the sacred paper (see the ES+PT incident one year ago).
we spent centuries building a system to track who owns what land and then put the whole thing in one database that can be deleted with a single compromised password
72 comments
[ 2.5 ms ] story [ 47.5 ms ] threadSo it seems not all has been lost. I was worried about the societal implications of being unable to prove land ownership but it seems that may be avoided.
Even if the digital records were completely lost, they still have the paper ones.
> being unable to prove land ownership
People know who owns what, there are also paper contracts of ownership which are more authoritative than the digital records.
The last thing any government will want to deal with is massive irretrievable data loss.
https://www.youtube.com/watch?v=K_FrQnQv0Vw
accidental communism
If the hacker was targeting the erasure of a particular recent transaction, they may well have succeeded. And by deleting numerous others, they have plausible deniability in the subsequent dispute over the property. If you just wipe a record that is related to you, and the manipulation is discovered (which it will be, one way or another), you are part of a narrow circle of suspects.
I had a copy of our code on media in my desk labeled “promotion” and updated it every month. In retrospect someone going through my desk would have assumed blackmail material and been disappointed to find only code.
The digital copy is just that; a digital copy.
The hacker would have to destroy the database and all backups, and also burn down the building holding the registry.
People would get their buddy to agree the land was theirs so not a perfect system, but some families were made more whole.
Moving from a paper registry at each county clerk (in the US) was a part of the 2008 financial meltdown.
Specifically:
- government gives IT/data contracts to cronies
- cronies don't actually do any real security work to protect the data
- things like this happen
A close relative, government employee, was in charge of building a new application. They have nobody in that entire organization of several thousands people that know how to write specifications for an IT application, nobody that knows how to design, test and deploy it. This is because some government employees have decent salaries, but in IT the private sector is paying a lot more, so almost anyone remotely competent is going to the private sector. So in this case an organization of non-IT people had to deal with the contract and all the associated problems - there is no need to guess, it did not go well. That kind of project could have been done properly with ~ 10% of the budget in the same timeline.
I have a friend that worked as a developer in such a government IT project. The project cost was ~ 5-10 times what was worth, a chain of sub-contractors did the work, less than ten competent people doing the project, charged by the bid winner for over 100 people and actual staff was around 70 at most, for a short period of time.
Both projects above are in Romania. Lack of competent people in the projects, especially in decision roles, was the main problem.
In this case I expect an underpaid employee, and at most an incompetent nephew of someone. They had no reason to have an .authorized_keys file in the webroot of the website, and yet they did.
If you want to know what "dedicated contracts" look like in practice they are overly specific requirements than can only match a single business. The best example that comes to mind was when one county needed to buy busses (or vans) and the maximum length admitted was bellow the most common options, but as luck would have it a nephew of a cousing of someone with decision power (or something like that) just so happened to be the one importing cars that precisely matched the specs.
ANCPI announced that it had begun migrating its applications to Romania’s Government Cloud. The operation is being coordinated by the Special Telecommunications Service (STS) and is expected to be completed on Wednesday, July 22.
After the migration, authorized institutions will inspect the applications and data and prepare a report on the condition of the systems and any additional measures required. Based on that report, ANCPI will announce an estimated date for restoring its applications. Services will be brought back online gradually, according to operational priorities.
ANCPI says it is rebuilding its database from backup copies stored in several locations. The agency rejected reports suggesting that it did not have sufficient backups, explaining that the use of multiple storage locations provides redundancy and allows data to be restored after cybersecurity incidents.
According to ANCPI, affected systems must remain isolated until every identified vulnerability has been addressed. Although shutting down the services has caused temporary inconvenience, the agency says the measure was necessary to protect the data and ensure that operations restart safely and reliably.
The restoration of the IT infrastructure is described as a complex process being conducted in cooperation with the relevant authorities. ANCPI has also confirmed that a criminal investigation is underway, but no official conclusions can yet be released.
The agency warned that claims circulating publicly about the alleged consequences of the attack are not based on official information and do not reflect the current state of the investigation.
The dumb thing was the bank was two blocks from the data center and less than eight (six?) from the office so catastrophic events might have hit both or all three. The owner kept a second copy at his house, and that was the only geographically separated copy.
One of the lessons (and subsequent data integrition / continuity of business practices) learned from the 9/11 attacks in New York City, and destruction of both primary and secondary data stores of multiple entities (as well as several emergency-response agencies at various government levels from city to federal) was that essential data and operational roles need to be redundant across very widely-separated locations.
E.g.: from "Discussion note prepared by staffs of the Federal Reserve, the New York State Banking Department, the Office of the Comptroller of the Currency, and the Securities and Exchange Commission, for discussion at a meeting on February 26, 2002 at the Federal Reserve Bank of New York":
[I]t was clear that business continuity planning had not fully taken into account the potential for wide-area disasters and for major loss or inaccessibility of critical staff. Contingency planning at many institutions generally focused on problems with a single building or system. Some firms arranged for their backup facilities to be in nearby buildings on the assumption that, for example, a fire might incapacitate or destroy a single facility. Very few planned for an emergency disrupting an entire business district, city, or region. As a result, some firms lost access to both their primary and backup facilities in the aftermath of the September 11 events, severely disrupting their operations.
"Summary of "Lessons Learned" from Events of September 11 and Implications for Business Continuity" February 13, 2002" <https://www.sec.gov/divisions/marketreg/lessonslearned.htm>
Geographic distances were rarely considered prior to 9/11. Most companies were comfortable replicating data intercampus or to a facility within a few miles of a primary data center. A few firms, such as Nasdaq, actually replicated data out of state.
"9/11: Top lessons learned for disaster recovery" (Sep 9, 2011) <https://www.computerworld.com/article/1545389/9-11-top-lesso...>
Also: "Hard-Earned Disaster Recovery Lessons From 9/11 and other disasters" (2025) <https://backupcentral.com/hard-earned-disaster-recovery-less...>
Terrorist attacks, natural disasters, widespread power and other failures, etc., can all have impacts across many kilometres, possibly many hundreds. Redundancy equates to survivability here.
More broadly, information and data services are fundamentally about risk management and disaster response, as realised during 9/11 (as well as multiple earlier and subsequent incidents) in ways which weren't fully realised at the turn of the millennium. Or even today in some organisations.
Make backups. Test backups. Practice switchovers between primary and secondary (or multiple redundant) operations. And keep those resources and facilities widely separated.
This, to me, is the more interesting bit of the article.
I don't really know what a good solution looks like, but yeah, that's annoying.
Algeria has a extradition treaty with Romania:
https://periodicos.processus.com.br/index.php/egjf/article/v...
Possibly since 1086
https://en.wikipedia.org/wiki/Domesday_Book
Before phones, if you moved between two affluent areas there was enough surplus capital in both that instead of hauling a heavy chest of silver coins between them and risking getting Robin Hooded you turn your coins in at one end of the trip and get reimbursed by a fellow in the same money handling cooperative at the other end, and then they would square their books through traders moving money the opposite direction or if necessary by armed escort.
There are MMO economies that either ban the flow of real money into the game, or only allow it to enter the game and not leave. In the case of the latter, poorer players trade their time and skill for something transferable in the game, such as rare items, or in the case of Eve Online, one free month of play time. There are Eve players who only ever payed for the first couple months in the game and then found a revenue stream that was subsidized by other players buying excess play time and selling it in-game when the demand drives the price up high enough to be attractive.
There's a growing (retarded) perspective, not only here in Romania but in most of the EU, that we must digitalize at all costs; this itself is obviously not a problem, but it usually comes with the removal of the "traditional" options too. The same goes for payments (removal of cash) and basically every aspect of the administration/society where this could be applied. The most recent concrete example for Romania is the mandatory digital signature by ANAF (IRS equivalent) for all companies.
Unlike other regions of the West: NA/WE/rest of the West (SK, JP, etc.), in EE, people (*younger generations, explained below) don't often think about the aspects of confidentiality that much, or if they do, they usually apply it incorrectly (either IRL [filming in public] or online ["I've accepted a draconian TOS that gives the company rights to all of my data, but I haven't actually read any of it, and now I'm invoking my "GDPR rights" against said company."]).
It does not take a genius or a historian to observe that while the older generations do not have this "problem" (they're very skeptical of the gov. [at least in certain aspects], in an almost american fashion — explained by the fact that they've experienced communism), younger generations position themselves in the extreme opposite; they despise the older generations ("boomers") for being luddites and somehow blame them for the gap in civilizational progress between WE and EE. There is a legitimate point here, of course, but it should be noted that the argument is almost always presented in an emotional, overwhelmingly irrational fashion, and almost never includes comparisons between the centralization done by the state in the past [communists] and the new one attempted by current govs [but digitalized]. (This delves into a broader socio-cultural divide between the generations that includes other aspects like religion, traditions, etc.)
The biggest portion of the so-called "IT people" who call for this "digitalization wave" are midwits, "inverse luddites" (they don't care about the implications), and, in smaller numbers, grifters and second-order beneficiaries (on the "digitalization" gov. projects). Obviously, it should be mentioned that, despite progress, nepotism and corruption are still present, and there are cases where gov. contracts are not given to the best candidate.
As a person who's both working in the IT sector and not a boomer (despite the impression of my comment), "we" should be careful about enabling totalitarians in our endeavors."Hackers" is just one reason out of a multitude of other reasons for not abandoning the sacred paper (see the ES+PT incident one year ago).